Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2024-42637 H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. R3010 Firmware No fix yet Fix from $2,3002024-08-16 CRITICAL 9.8 CVE-2024-42638 H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. Magic B1st Firmware No fix yet Fix from $2,3002024-08-16 MEDIUM 6.8 CVE-2024-31798 Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the … Gncc C2 Firmware No fix yet Fix from $1,6002024-08-15 CRITICAL 9.8 CVE-2024-41161 Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 a… Var1200 H Firmware after 3.3.23.6.9 Fix from $2,3002024-08-08 HIGH 8.8 CVE-2024-6890 Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can brut… Journyx No fix yet Fix from $1,9502024-08-07 CRITICAL 9.8 CVE-2024-41616 D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. Dir 300 Firmware No fix yet Fix from $2,3002024-08-06 HIGH 8.8 CVE-2024-39838 ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative… Zwx 2000csw2 Hn Firmware 0.3.15+ Fix from $1,9502024-08-05 MEDIUM 6.6 CVE-2024-33895 Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is… Ewon Cosy\+ Firmware after 22.1s3 Fix from $1,6002024-08-02 CRITICAL 9.8 CVE-2024-7332EPSS 21% A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_… Cp450 Firmware No fix yet Fix from $2,3002024-08-01 CRITICAL 9.8 CVE-2024-41610 D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the T… Dir 820lw Firmware Mitigation only Fix from $2,3002024-07-30 CRITICAL 9.8 CVE-2024-41611 In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Tel… Dir 860l Firmware Mitigation only Fix from $2,3002024-07-30 HIGH 8.8 CVE-2024-7170 A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /we… A3000ru Firmware No fix yet Fix from $1,9502024-07-28 CRITICAL 9.8 CVE-2024-6912 Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue af… Processplus after 1.11.6507.0 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-5471 Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys. Manageengine Ddi Central 4002+ Fix from $2,3002024-07-17 CRITICAL 9.8 CVE-2024-35338 Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. I29 Firmware No fix yet Fix from $2,3002024-07-16 MEDIUM 5.3 CVE-2024-5810 The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and i… Mitigation only Fix from $1,6002024-07-09 CRITICAL 9.1 CVE-2024-28751 An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. No fix yet Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-28747 An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges. Mitigation only Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2023-46685 A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially cra… Wbr 6013 Firmware Mitigation only Fix from $2,3002024-07-08 CRITICAL 9.8 CVE-2024-4708 mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. Mypro 8.31.0+ Fix from $2,3002024-07-02 CRITICAL 9.8 CVE-2023-41919 Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access. P2 Firmware after 4.8.2605 Fix from $2,3002024-07-02 CRITICAL 9.8 CVE-2024-39208 luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. No fix yet Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-39374 TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded cre… Markoni D \(compact\) Firmware 2.0.1+ Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-0949 Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektra… Mitigation only Fix from $2,3002024-06-27 HIGH 7.5 CVE-2024-33329 A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive i… Mitigation only Fix from $1,9502024-06-26 HIGH 8.1 CVE-2024-5460 A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 c… Fabric Operating System 9.0.0+ Fix from $1,9502024-06-26 CRITICAL 9.3 CVE-2023-6198 Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the de… Mitigation only Fix from $2,3002024-06-25 HIGH 7.5 CVE-2024-36496 The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. … Mitigation only Fix from $1,9502024-06-24 CRITICAL 9.8 CVE-2024-36480 Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker ma… Mitigation only Fix from $2,3002024-06-19 HIGH 8.8 CVE-2024-6045EPSS 6% Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can fo… Mitigation only Fix from $1,9502024-06-17